Managing macOS devices using Microsoft Intune
The profile can be corrected and re-pushed from the Microsoft side, but only by the Intune (or other MDM) administrator that manages the device. It cannot be removed or changed locally on the Mac if it is an MDM-managed configuration profile.
To address the issue from the Microsoft/Intune side, the Intune admin should:
- Identify the managing MDM and profile
- On the Mac, open System Settings > Privacy & Security > Profiles (or Profiles in older macOS versions) and note:
- The MDM/management profile name (for example, “Management profile”, “Intune MDM”, or similar).
- Any Firewall, Network, or Security configuration profiles that could affect network or file sharing access.
- This confirms which MDM tenant/profile is controlling the device.
- On the Mac, open System Settings > Privacy & Security > Profiles (or Profiles in older macOS versions) and note:
- Review Intune firewall and network-related policies for macOS
In the Intune admin center, the admin should check for policies that could block SMB/file share access for certain users:
- Endpoint security > Firewall (macOS firewall profile)
- Go to Endpoint security > Firewall and look for macOS firewall policies assigned to this device or its user group.
- In the macOS firewall profile, review:
- Enable Firewall: If set to Yes, check:
- Block all incoming connections – if set to Yes, this can block sharing services and may affect access patterns.
- Firewall apps rules – verify that there is no app rule that blocks the process used for file sharing or VPN/agent needed for shared drive access.
- Adjust the policy if it is overly restrictive and then save the changes.
- Enable Firewall: If set to Yes, check:
- Other macOS configuration profiles
- In Devices > Configuration, filter by Platform: macOS and review:
- Any Custom profiles (for example,
.mobileconfigimports) that might contain network filters, proxies, or restrictions. - Any Network filter or Microsoft Defender network protection policies that could be blocking SMB or the specific shared drive host.
- Any Custom profiles (for example,
- In Devices > Configuration, filter by Platform: macOS and review:
- Endpoint security > Firewall (macOS firewall profile)
- Confirm assignment scope (why only one account is affected)
- In each relevant policy (Firewall, Defender, Custom profiles), check the Assignments:
- See if the policy is assigned to a user group that includes only the affected account.
- Other accounts on the same Mac may be in different groups or excluded from the policy.
- If needed, either:
- Remove the affected user from that group, or
- Adjust the policy so it no longer blocks the required shared drive access.
- In each relevant policy (Firewall, Defender, Custom profiles), check the Assignments:
- Re-push (reapply) the corrected profile
- After editing the policy, Intune will automatically re-apply it to targeted devices.
- To speed this up:
- In Intune, go to Devices > select the Mac > Sync.
- On the Mac, open Company Portal (if installed) and trigger a Check status / Sync.
- If the profile must be removed instead of corrected
- In Intune, the admin can:
- Unassign the problematic profile from the affected user/device group, or
- Delete the profile entirely if it is no longer needed.
- Once removed, sync the device from Intune and from the Mac (Company Portal) to clear the settings.
- In Intune, the admin can:
- If the Mac was cloned from another managed Mac
- Because the Mac was built from an image of another managed Mac, its management state and serial/identity may be inconsistent with the current tenant configuration.
- The Intune admin should verify that:
- The Mac’s serial number is correctly enrolled and associated with the correct user.
- There are no conflicting device records for the same serial in Intune.
- If necessary, the admin can:
- Remove the old device record from Intune.
- Wipe or unenroll the Mac properly and then re-enroll it so it receives a clean, correct set of profiles.
In summary, the profile cannot be removed from the Mac side if it is MDM-managed, but it can absolutely be corrected or removed in Intune and then re-pushed. The Intune admin should focus on macOS firewall and network-related profiles and their assignments, then sync the device so the updated configuration takes effect.
References: